Abstract

Large language models (LLMs) are increasingly deployed in privacy-critical domains (e.g., healthcare, finance, and government), but their propensity to memorize and disclose personally identifiable information (PII) poses serious security and compliance risks. Existing defenses typically force a trade-off between model utility, privacy protection, and access to fine-tuned private knowledge. We propose LoRA-Oriented Control via Keyed Entry Tokens (Locket), a practical framework that embeds fine-grained, policy-driven access control directly into LLM generation. Locket trains a set of lightweight LoRA (Low-Rank Adaptation) adapters, each encoding a distinct access policy (e.g., full reveal, partial redaction via PII masking, or reveal under a specified differential privacy level). A compact gating module is trained to associate a learned keyed entry token with exactly one LoRA adapter via sequence-level hard routing; the presence of a valid token acts as an authorization key that unlocks corresponding private knowledge, while an invalid or absent token triggers a privacy-preserving adapter that redacts or sanitizes sensitive content. This design ensures Locket remains fully compatible with off-the-shelf LLMs, supporting scalable deployment while satisfying regulatory and privacy requirements. We evaluate Locket across multiple datasets (Enron, ECHR, Yelp) and a diverse set of state-of-the-art LLMs, including Qwen3 (1.7B and 8B), Meta's Llama-3.2 (1B and 3B), and Google's Gemma-2-2B. Our extensive experiments demonstrate that, when the correct token is provided, Locket preserves perplexity comparable to fine-tuning on raw data (without any defense). Conversely, when the token is missing or invalid, it substantially reduces PII leakage while maintaining utility and perplexity on par with strong baseline defenses.

Keywords

Subject

Publication details

Journal
Not available
Open access
Green open access

Cite this article

APA 7

Shaaban, M., & Elmahallawy, M. (2026). Tokenized Key-Gated Adapter Routing: A Secure Access Control Mechanism Against Private Data Leakage in LLMs. https://omanscience.com/en/articles/tokenized-key-gated-adapter-routing-a-secure-access-control-mechanism-against-private-data-leakage-in-llms

MLA 9

Shaaban, Mohamed, and Mohamed Elmahallawy. "Tokenized Key-Gated Adapter Routing: A Secure Access Control Mechanism Against Private Data Leakage in LLMs." https://omanscience.com/en/articles/tokenized-key-gated-adapter-routing-a-secure-access-control-mechanism-against-private-data-leakage-in-llms.

Chicago (author–date)

Shaaban, Mohamed, and Mohamed Elmahallawy. 2026. "Tokenized Key-Gated Adapter Routing: A Secure Access Control Mechanism Against Private Data Leakage in LLMs." https://omanscience.com/en/articles/tokenized-key-gated-adapter-routing-a-secure-access-control-mechanism-against-private-data-leakage-in-llms.

Harvard

Shaaban, M. and Elmahallawy, M. (2026) 'Tokenized Key-Gated Adapter Routing: A Secure Access Control Mechanism Against Private Data Leakage in LLMs', Available at: https://omanscience.com/en/articles/tokenized-key-gated-adapter-routing-a-secure-access-control-mechanism-against-private-data-leakage-in-llms.

Vancouver

Shaaban M, Elmahallawy M. Tokenized Key-Gated Adapter Routing: A Secure Access Control Mechanism Against Private Data Leakage in LLMs. https://omanscience.com/en/articles/tokenized-key-gated-adapter-routing-a-secure-access-control-mechanism-against-private-data-leakage-in-llms

IEEE

M. Shaaban, and M. Elmahallawy, "Tokenized Key-Gated Adapter Routing: A Secure Access Control Mechanism Against Private Data Leakage in LLMs," https://omanscience.com/en/articles/tokenized-key-gated-adapter-routing-a-secure-access-control-mechanism-against-private-data-leakage-in-llms.